Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4969

Опубликовано: 21 мая 2025
Источник: debian

Описание

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.5-2package
libsoup3no-dsabookwormpackage
libsoup2.4unfixedpackage
libsoup2.4no-dsatrixiepackage
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/447

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/467

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
redhat
4 месяца назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
nvd
4 месяца назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
github
4 месяца назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость библиотеки libsoup графического интерфейса GNOME, позволяющая нарушителю получить доступ к конфиденциальной информации